Linked by Thom Holwerda on Mon 3rd Sep 2012 21:53 UTC
Thread beginning with comment 533870
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
Features
Linked by Thom Holwerda on 05/21/13 21:38 UTC
Linked by Thom Holwerda on 05/20/13 11:29 UTC
Linked by Thom Holwerda on 05/18/13 21:33 UTC
Linked by David Adams on 05/16/13 4:23 UTC
Linked by Thom Holwerda on 05/11/13 21:41 UTC
Linked by Thom Holwerda on 05/08/13 14:22 UTC
Linked by Thom Holwerda on 05/02/13 15:28 UTC
Linked by Thom Holwerda on 04/29/13 21:06 UTC
Linked by Thom Holwerda on 04/24/13 22:24 UTC
Linked by Thom Holwerda on 04/18/13 11:21 UTC
More Features »
Sponsored Links



Member since:
2009-03-06
This sounds like use of a virtual machine monitor (Xen, in this case) to provide separation between applications, some drivers, and other processes, and to run them in an unprivileged mode. Something that things like Minix and most true microkernel OSes do without the VMM
.
Is it more secure than Linux chroot? Probably. More secure than FreeBSD jails/UML/<your favorite app virtualization scheme here>? Depends on how secure you think Xen is. It's a fairly substantial amount of code regardless. Unless Qubes can run any general-purpose OS in one of the "appVM"s, I think the effort would probably have been better spent on one of the other technologies mentioned above.